Weaknesses of type CWE-502

2,668 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2023-37227CRITICALLoftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.EPSS 0.6%CVE-2025-2689MEDIUMyiisoft Yii2 SortableIterator.php getIterator deserializationEPSS 0.6%CVE-2023-28782HIGHWordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2025-27286CRITICALWordPress Saoshyant Slider Plugin <= 3.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-52207CRITICALWordPress HTML5 MP3 Player with Playlist Free Plugin <= 3.0.0 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2025-32572CRITICALWordPress Kata Plus Plugin <= 1.5.3 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-27287CRITICALWordPress SS Quiz Plugin <= 2.0.5 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-92785CRITICALAngel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary ClassesEPSS 0.6%CVE-2025-71342HIGHpicklescan - Undetected Remote Code Execution via idlelib.run.Executive.runcodeEPSS 0.6%CVE-2025-71349HIGHpicklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickle FilesEPSS 0.6%CVE-2026-35464HIGHpyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code executionEPSS 0.6%CVE-2025-71359HIGHpicklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loadsEPSS 0.6%CVE-2025-71345HIGHpicklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_autograd_profEPSS 0.6%CVE-2025-71341HIGHpicklescan - Remote Code Execution via Undetected profile.Profile.runctxEPSS 0.6%CVE-2026-44963CRITICALA vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.EPSS 0.6%CVE-2026-78032CRITICALSOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privEPSS 0.6%CVE-2025-66571CRITICALUNA CMS 9.0.0-RC1 - 14.0.0-RC4 PHP Object InjectionEPSS 0.6%CVE-2026-67579HIGHFilter expression injection via forged keyset pagination cursor in AshEPSS 0.6%CVE-2023-27459HIGHWordPress User Registration plugin <= 2.3.2.1 - Authenticated PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-3857HIGHInfinite loop condition in Amazon.IonDotnetEPSS 0.6%